Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023Suministrador Ibérico de Energía, S.L.Suministrador Ibérico de Energía, S.L. was fined by the AEPD €70,000 for switching a customer's electricity provider without consent. The authority found that the processing lacked a valid legal basis under Article 6(1) GDPR.ESAEPDGDPR€70,000
01 Jan 2020Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for unauthorized charges on a customer's account. The authority found a breach of Article 6(1) GDPR, indicating processing without a valid legal basis.ESAEPDGDPR€70,000
01 Jan 2019Xfera Móviles, S.A.Xfera Móviles, S.A. was fined by the AEPD 70,000 EUR for the unauthorized disclosure of personal data caused by an error. The authority found a breach of the GDPR principle of integrity and confidentiality.ESAEPDGDPR€70,000
07 Mar 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card to a third party without proper identity verification. The incident enabled unauthorized access to a bank account and resulted in financial loss.ESAEPDGDPR€70,000
04 May 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a SIM card duplicate without verifying the requester’s identity. The failure enabled unauthorized access to a bank account and caused financial loss to the complainant.ESAEPDGDPR€70,000
01 Jan 2022VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 70,000 EUR for unlawfully accessing a creditworthiness file. The company used an individual's tax ID without legitimate grounds, breaching data protection rules.ESAEPDGDPR€70,000
15 Jul 2022BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle.ESAEPDGDPR€70,000
08 Feb 2023VODAFONE SERVICIOS, S.L.U.VODAFONE SERVICIOS, S.L.U. was fined by the AEPD 70,000 EUR for a SIM card duplication incident. The incident resulted in identity theft and unauthorized access to a bank account, indicating a breach of data protection rules.ESAEPDGDPR€70,000
01 Jan 2021ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings.ESAEPDGDPR€70,000
02 Feb 2023DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without the complainant's consent. The incident led to attempts to gain unauthorized access to the complainant's bank accounts.ESAEPDGDPR€70,000
03 Aug 2022Telefónica Móviles España, S.A.U.Telefónica Móviles España, S.A.U. was fined EUR 70,000 by the AEPD for providing a SIM card duplicate to a third party without the data subject’s consent. The authority found this conduct to be a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
04 Jul 2021VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a third party to contract phone numbers using another individual's identity. The case concerns a breach of data protection rules and inadequate identity verification.ESAEPDGDPR€70,000
16 Nov 2023Intelling LtdBetween 1 January 2021 and 11 November 2021, Intelling sent 1,164,877 direct marketing messages in breach of Regulation 22 of PECR. The Commissioner opened the case after receiving 1,103 complaints via the 7726 Spam Reporting Service.GBICOePrivacy€79,982
01 Jan 2023ENERGÍA COLECTIVA, S.L.ENERGÍA COLECTIVA, S.L. was fined by the AEPD for inaccurately processing personal data. The issue led to incorrect billing and an intrusion into individuals’ privacy.ESAEPDGDPR€70,000
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
06 Apr 2022BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error.ESAEPDGDPR€70,000
05 Jul 2022CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules.ESAEPDGDPR€70,000
28 Jun 2022DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined EUR 70,000 by the AEPD for a SIM card duplication incident. The incident enabled unauthorized attempts to access the complainant's bank accounts and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€70,000
28 Feb 2023TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD 70,000 EUR for processing personal data without consent. The case concerned a mobile line contracted in the complainant’s name without proper identity verification.ESAEPDGDPR€70,000
22 Feb 2022VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for issuing a duplicate SIM card to a third party without proper authorization. This enabled unauthorized access to the complainant’s bank data and resulted in fraudulent transactions.ESAEPDGDPR€70,000